uninstall.exe

Krance Development

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application uninstall.exe by Krance Development has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program PalMall by BND. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Krance Development  (signed and verified)

MD5:
273ada46369f816e3596308575a85a59

SHA-1:
6397ad48b8cdeb4da0ed47f540f9735626c51fc3

SHA-256:
1c2bbbea379982aa7648c3e30908b3ad25b6957d6dbfcf73b32b8685cc047696

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/2/2024 11:19:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle (M)
17.3.4.18

File size:
84.9 KB (86,944 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\palmall\uninstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/27/2014 9:00:00 PM

Valid to:
8/28/2015 8:59:59 PM

Subject:
CN=Krance Development, O=Krance Development, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2F8A4746EB05936853BC17805C72D300

File PE Metadata
Compilation timestamp:
10/6/2014 4:41:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x4D2B

Entry point:
E8, 10, 59, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 28, 2E, 41, 00, E8, 1F, 0A, 00, 00, E8, 7E, 24, 00, 00, 0F, B7, F0, 6A, 02, E8, A3, 58, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 84, 52, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
51 KB (52,224 bytes)

Program Uninstaller
Program name:
PalMall

Display publisher:
BND

Display version:
1.35.9.29

Uninstall string:
C:\Program Files (x86)\PalMall\Uninstall.exe /fcp=1


Remove uninstall.exe - Powered by Reason Core Security